Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 1.7%top 24%

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.5 (ROCm)

0
High
Published: 12/17/2025 (12/17/2025, 08:22:31 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat® AI Inference Server

Affected software

Affected versions
Red HatRed Hat AI Inference ServerRed Hat AI Inference Server 3.2amd64registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:c5efe40fa2a6e98d7d3d6676befff0dbbd87b2887769bb7e5856c5b0b0ada125_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 13:26:04 UTC

Technical Analysis

Red Hat AI Inference Server 3.2.5 (ROCm) is affected by multiple security vulnerabilities identified under CVE-2025-9230 and 10 additional CVEs. These vulnerabilities correspond to several CWE categories including buffer overflow (CWE-787), improper input validation (CWE-606), code injection (CWE-94), and others. The Red Hat security advisory RHSA-2025:23449 acknowledges these issues but does not list any available fixes or patches at this time. The product is not a cloud service, so remediation depends on vendor patch releases. No known exploits in the wild have been reported as of the advisory date.

Potential Impact

The vulnerabilities collectively pose a high risk to the affected Red Hat AI Inference Server 3.2.5 (ROCm) installations. Potential impacts include unauthorized code execution, denial of service, and other security breaches due to the nature of the weaknesses (buffer overflows, improper validation, code injection). However, no active exploitation has been reported yet. The lack of an available patch means affected systems remain vulnerable until a fix is released.

Mitigation Recommendations

As per the Red Hat advisory RHSA-2025:23449, no fixes or patches are currently available for these vulnerabilities in Red Hat AI Inference Server 3.2.5 (ROCm). Users should monitor Red Hat's official security updates for the release of patches. Until a fix is provided, consider limiting exposure of the affected server and applying any relevant workarounds recommended by Red Hat if available. Avoid speculative or generic mitigations not directly related to the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:23449
Cve Count
11
Additional Cves
["CVE-2025-9714","CVE-2025-22868","CVE-2025-22869","CVE-2025-47906","CVE-2025-52565","CVE-2025-59375","CVE-2025-62164","CVE-2025-62372","CVE-2025-66448","CVE-2025-66506"]
Cvss Version
null

Threat ID: 6a16097ae29bf47b5064673b

Added to database: 05/26/2026, 20:58:34 UTC

Last enriched: 07/30/2026, 13:26:04 UTC

Last updated: 08/05/2026, 00:41:11 UTC

Views: 78

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses